Enterprises hit by data breaches continue to adopt the faulty practice of playing a blame game on the most susceptible targets for those attacks — non-IT employees.
Security vendors and their customers want to reduce the number of incidents. The FBI’s Internet Crime Complaint Center (IC3) reported that over the last five years, data breaches in the U.S. have resulted in losses of more than $19 billion.
Ian McShane, VP of strategy at Arctic Wolf, believes there’s another side to this. In an interview with SDxCentral, McShane says companies should want to see an increase in incidents reported. And there’s a good argument why.
“Most organizations, if someone screws up and falls for a phishing attack, they're not going to actively put their hand up and say, yeah, sorry, I've done something wrong, because they're worried about getting beaten by the punishment stick,” McShane said “We need to make security inclusive and open for everyone. That means that we're encouraging people to point out, hey, I made a mistake.”
The cybersecurity skills gap contributes to fewer reported incidents among non-technical employees, which leaves businesses at more risk of attacks. A recent Cybersecurity Trends report from Arctic Wolf found 76% of respondents said the primary obstacle keeping them from achieving their cybersecurity objectives is a lack of security expertise among staff.
Arctic Wolf Finds a Skills GapIn the same Arctic Wolf report, 90% of cyberattacks target an organization's employees. What’s easy for security and IT employees to understand in regards to functional cybersecurity practices is oftentimes a foreign language for non-technical users. “It’s no wonder that end users get frustrated and confused and ultimately put themselves at risk,” McShane said.
Annual cybersecurity training, whether it be data protection or privacy training, is often a compliance check rather than education for non-technical employees. One thing that organizations should be doing is having a better cadence of security training, which can build more interest and support around security. Arctic Wolf found that 38% of companies are not using some form of security awareness program.
Weekly or bi-weekly touch points that require little commitment from employees go a lot further than companies expecting hours of commitment from their employees in one sitting.
“Education through videos or through quizzes to keep people engaged almost all the way through the year to keep them thinking about cybersecurity is vital,” McShane said.
Companies must re-evaluate their security practices instead of disregarding security training for non-technical employees.
At the end of the day, the more incidents non-technical employees are reporting can actually bridge a company’s cybersecurity skills gap. “That means that people are paying attention, No. 1. … And more non-technical people can recognize their mistakes and be confident that security isn’t just a punishment arm but it’s actually going to be useful for them.”
Comments